Navigating PCI DSS 4.0: Insights from Industry Experts on Client-Side Security
ID: 932c1031-45d0-5df2-950b-94a4f4facf77
STIX ID: report--932c1031-45d0-5df2-950b-94a4f4facf77
Feed Name: Security Boulevard
This blog summarizes a QSA roundtable on PCI DSS v4.0’s expanded client-side security requirements (notably 6.4.3 and 11.6.1), highlighting the rising risk of eSkimming/Magecart and formjacking, and the need to inventory, authorize, and verify the integrity of scripts on payment pages. Panelists emphasize that even sites using redirects/iframes are now in scope, note the operational challenges of maintaining script inventories, and describe the practical limits of CSP/SRI in dynamic environments. The key recommendation is to adopt automated, real-time client-side monitoring and control solutions to meet the April 2025 compliance timeline and reduce exposure to client-side data theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
